seeing is believing

Debian Security Advisory 2791-1

Debian Security Advisory 2791-1
Posted Nov 4, 2013
Authored by Debian | Site debian.org

Debian Linux Security Advisory 2791-1 - Cedric Krier discovered that the Tryton client does not sanitize the file extension supplied by the server when processing reports. As a result, a malicious server could send a report with a crafted file extension that causes the client to write any local file to which the user running the client has write access.

tags | advisory, local
systems | linux, debian
MD5 | 196f803138298602ee76f92ac26f1181

Debian Security Advisory 2791-1

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- -------------------------------------------------------------------------
Debian Security Advisory DSA-2791-1 security@debian.org
http://www.debian.org/security/ Florian Weimer
November 04, 2013 http://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : tryton-client
Vulnerability : missing input sanitization
Problem type : remote
Debian-specific: no

Cedric Krier discovered that the Tryton client does not sanitize the
file extension supplied by the server when processing reports. As a
result, a malicious server could send a report with a crafted file
extension that causes the client to write any local file to which the
user running the client has write access.

For the oldstable distribution (squeeze), this problem has been fixed in
version 1.6.1-1+deb6u1.

For the stable distribution (wheezy), this problem has been fixed in
version 2.2.3-1+deb7u1.

We recommend that you upgrade your tryton-client packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iQEcBAEBAgAGBQJSd0JkAAoJEL97/wQC1SS+yxIIAKhE710knodmQwpAoCSobSwp
3cK7RK7PIMkiyAfLnNi646cU0xXGWydgwydxvm1VyULBtsBbaOaEXzOu8j2eOYVR
WQeUEy3kiDGE3J38QUzaf0MGejZI3jZQRERkYIxEOkEvsHZqZYLLe+BOvOt1Nz2T
vMMRqCjcAN+k1eE271tL9omWZxpsVCFG0uIGwfTmpCgf7QGKqnlnuMfrpeDQ+7/3
8VOE6EOrIBbFdXeXxW/TKM94Z8HGGkpU+GUJ2FiMyF0q0e8e4n2JG0sldnIeM9RF
cSrv5550JSSGgCLh3t3JtBTCsvQMGfnPKKdvx781vIz0inTgXy2SFAYaUukBPks=
=ZvvC
-----END PGP SIGNATURE-----

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

July 2017

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    2 Files
  • 2
    Jul 2nd
    3 Files
  • 3
    Jul 3rd
    15 Files
  • 4
    Jul 4th
    4 Files
  • 5
    Jul 5th
    15 Files
  • 6
    Jul 6th
    15 Files
  • 7
    Jul 7th
    10 Files
  • 8
    Jul 8th
    2 Files
  • 9
    Jul 9th
    10 Files
  • 10
    Jul 10th
    15 Files
  • 11
    Jul 11th
    15 Files
  • 12
    Jul 12th
    19 Files
  • 13
    Jul 13th
    16 Files
  • 14
    Jul 14th
    15 Files
  • 15
    Jul 15th
    3 Files
  • 16
    Jul 16th
    2 Files
  • 17
    Jul 17th
    8 Files
  • 18
    Jul 18th
    11 Files
  • 19
    Jul 19th
    15 Files
  • 20
    Jul 20th
    15 Files
  • 21
    Jul 21st
    15 Files
  • 22
    Jul 22nd
    7 Files
  • 23
    Jul 23rd
    1 Files
  • 24
    Jul 24th
    19 Files
  • 25
    Jul 25th
    1 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2016 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close